CCAS · Study Kit · Independent Prep · 2026

Certified Cryptoasset AFC Specialist Exam Guide

Condensed notes, case files, a glossary, a 170-card flashcard drill and a 150-question bank that builds a fresh blueprint-weighted mock every attempt. Aligned to the v1.13 study guide.

100Questions (MC + multi-select)
175 minTime limit
75Passing score
3Domains: 30 / 35 / 35
0Penalty for guessing

How the CCAS exam works

Everything below reflects the official ACAMS candidate handbook and study guide structure. Verify current logistics on acams.org before booking, since fees and policies change.

Format

  • 100 questions in 175 minutes, delivered at a Pearson VUE test centre or via online proctoring. That is 1 minute 45 seconds per question with no scheduled breaks.
  • Two question styles: standard multiple choice (pick one) and multiple select (pick all that apply, the question states how many). Multi-select is all-or-nothing: partial credit is not awarded.
  • Passing score is 75. Some questions are unscored pilot items, but you cannot tell which, so treat every question as live.
  • No negative marking. Never leave a question blank.
  • You have 6 months from payment to sit the exam.

The three domains

CodeDomainWeightWhat it really tests
D1Cryptoasset and Blockchain30%How the technology works: blockchains, consensus, wallets, keys, transaction models, cryptoasset types, VASPs, mixers, DeFi, and on-chain analytics.
D2AML Foundations for Cryptoasset and Blockchain35%Financial crime typologies in crypto, the four risk categories (customer, jurisdiction, product, channel), red flags, and how KYC, monitoring and screening control that risk.
D3Risk Management Programs for Cryptoasset and Blockchain35%FATF and international standards, major jurisdiction regimes (US, EU, UK), risk assessment methodology, AML program design, investigations and reporting.
70% of the exam is D2 + D3. The technology domain matters, but the exam is won on risk, regulation and program design. If you work in compliance operations already, D1 is where the unfamiliar vocabulary lives, so do not skip it.

Eligibility and recertification

  • Complete the three ACAMS certificate courses first: Cryptoasset and Blockchain, AML Foundations for Cryptoasset and Blockchain, and Risk Management Programs for Cryptoasset and Blockchain. Each ends with a 20-question assessment, 80% to pass, unlimited attempts.
  • Hold an active ACAMS membership and 40 eligibility credits (education, experience, training).
  • The credential is valid for 3 years. Recertify with 30 credits, at least 15 from ACAMS training or events.

How to use this kit

  • Study Notes: one pass per domain, then the two cross-domain topics at the bottom: the case files and the ACAMS framings. Those framings are where points hide.
  • Flashcards: drill by domain, cases or glossary terms. "Again" recycles a card, "Got it" retires it.
  • Glossary: searchable, for the moment a term in a question stem looks unfamiliar.
  • Question Bank: 150 questions with instant explanations. Anything you miss here or in a mock lands in "My misses" so you can clear it.
  • Mock Exam: every attempt draws a fresh 100 at the 30/35/35 blueprint in 175 minutes, or a 25-question sprint in 44 minutes. Aim for 85% or better.

Study notes

Original condensed notes in plain language, organised to mirror the CCAS syllabus. Green boxes are exam magnets: definitions, numbers and distinctions the exam loves to test.

CCAS-D1 · 30%

Cryptoasset and Blockchain

Blockchain fundamentals and types

A blockchain is a decentralized, distributed ledger. Transactions are grouped into blocks, each block carries a cryptographic hash of the previous block, and the chain is replicated across many nodes. Changing a confirmed block would require re-mining every later block and out-computing the honest network, which is why the ledger is treated as immutable.

  • Nodes store and relay the ledger. Miners or validators verify transactions and add blocks. A miner's job is validation, not preventing account hacks.
  • Public: permissionless, anyone can read, transact and validate (Bitcoin, Ethereum). Transparent but energy-hungry and slower to scale.
  • Private: one organisation controls access and permissions. Fast, but few participants and lower transparency.
  • Consortium: semi-decentralized, run jointly by a group of organisations, common for banks and governments.
  • Hybrid: mixes public and private, with controlled access to some data.
Pseudonymous, not anonymous. Addresses are not natively tied to identity, but every transaction is permanently visible. Analytics firms attribute addresses using clustering heuristics and off-chain data. This one distinction feeds many exam questions.
Consensus: proof of work vs proof of stake
  • Proof of work: miners race to solve a hash puzzle (finding a nonce). Wins security through raw computation, costs enormous energy. Bitcoin.
  • Proof of stake: validators are selected in proportion to the coins they lock up as stake. Misbehaviour is punished by slashing the stake. Far lower energy use. Ethereum since the Merge.
  • Mining pools combine hash power and share rewards. Hash rate concentration and the geography of mining (energy costs, state bans, state-sponsored mining) create geopolitical risk.
Watch the swap trick. Distractor answers routinely give PoW the attributes of PoS (staking, slashing) or vice versa. Anchor: PoW = hardware and electricity. PoS = locked capital.
Cryptoasset types
  • Bitcoin: first widely adopted cryptoasset, UTXO model, capped supply of 21 million.
  • Altcoins: everything after Bitcoin. Ethereum added programmability: smart contracts and tokens.
  • Tokens are issued on top of an existing chain (ERC-20 and similar). An ICO sells new tokens to fund a project; historically a fraud-heavy channel with little investor protection.
  • NFTs are non-fungible: each token is unique and not interchangeable one-for-one, used for art, collectibles and in-game assets.
  • Privacy coins are built to obscure sender, receiver and amount. Monero uses ring signatures, stealth addresses and confidential amounts by default. Zcash offers optional shielded transactions using zero-knowledge proofs. Dash offers CoinJoin-style mixing.
  • Stablecoins: pegged to a reference asset. Asset-backed coins hold reserves (fiat, treasuries). Algorithmic coins defend the peg with mint-and-burn incentives and can collapse in a run, as TerraUSD did in May 2022.
  • CBDC: digital currency issued by a central bank as a direct liability of the state. Centralized by design, so it is not a cryptoasset in the decentralized sense.
Regulators say "virtual asset" (VA), the FATF term, to distinguish digitally native value from digitised fiat and from e-money. Cryptoasset, virtual asset and virtual currency largely overlap in exam usage; CBDC never belongs in that bucket.
Wallets, keys and custody
  • A wallet stores keys, not coins. The private key signs transactions: whoever controls it controls the funds. The public key derives the address people send to. A seed phrase regenerates the keys; lose both and the funds are unrecoverable.
  • Hot wallet: connected to the internet, convenient, higher theft exposure. Cold wallet: offline (hardware, paper), safest for bulk holdings. Sound VASP practice: bulk client assets cold, small operational float hot.
  • Custodial: a third party (usually a VASP) holds the keys for the customer. Non-custodial / self-hosted / unhosted: the user holds their own keys, with no intermediary applying KYC to the wallet itself.
"Not your keys, not your coins." Custody determines who can move funds and where regulatory obligations attach. Transfers between a VASP and self-hosted wallets are a recurring risk theme (see Travel Rule and EU TFR in D3).
Transactions: UTXO vs account model
  • UTXO model (Bitcoin): a transaction consumes unspent outputs as inputs and creates new outputs. Leftover value returns to the sender as a change output, often to a fresh change address. This complicates tracing but co-spending inputs reveals common ownership.
  • Account model (Ethereum): balances sit in accounts and transactions debit and credit them directly, like bank ledger entries, with a nonce ordering each account's transactions.
  • Buying crypto typically means: onboard at an exchange, pass KYC, fund with fiat, trade, then either leave assets in exchange custody or withdraw to a self-hosted wallet.
  • P2P transactions move value directly between users with no VASP in the middle, which removes the natural KYC checkpoint.
VASPs and business models

FATF defines a virtual asset service provider as a business conducting any of five activities for or on behalf of customers:

  • Exchange between virtual assets and fiat
  • Exchange between one or more forms of virtual assets
  • Transfer of virtual assets
  • Safekeeping or administration of virtual assets or instruments enabling control over them (custody)
  • Participation in and provision of financial services related to an issuer's offer or sale of a virtual asset
Own-account activity is not VASP activity. Mining for yourself, running a node, or spending your own crypto does not make you a VASP. The test is doing it as a business for others.
  • Centralized exchange (CEX): takes custody, runs an order book, applies KYC, is the classic regulated VASP.
  • Decentralized exchange (DEX): smart contracts and liquidity pools (AMMs) match trades, users keep custody, often no KYC and no clear operator, which is exactly the regulatory challenge.
  • Crypto ATMs: convert cash to crypto and back. Risk drivers: cash intensity, weak identification, and heavy use by scam and mule networks.
  • Lending services: VASPs paying yield on deposits or lending against crypto collateral add credit and concentration risk on top of AML risk.
  • DeFi, dApps and DAOs: financial services rebuilt as autonomous code with governance by token vote. Ownership and accountability are diffuse; FATF looks for the persons with control or sufficient influence when deciding who owes VASP obligations.
  • Mixers and tumblers: services that pool and commingle funds from many users and pay out to fresh addresses, deliberately breaking the on-chain link between source and destination.
Blockchain analytics, tracing and attribution
  • Clustering groups addresses likely controlled by one entity. The core Bitcoin heuristic is co-spend: inputs spent together in one transaction are presumed to share an owner. Change-address patterns extend clusters further.
  • Attribution labels clusters as real-world entities (exchanges, mixers, darknet markets, ransomware groups) using service interactions, undercover transactions and open-source intelligence.
  • Exposure measures how directly an address or transaction connects to a risky counterparty: direct (one hop) or indirect (several hops).
  • Tracing tools follow flows across hops, through peel chains and across chains. Privacy coins and mixers degrade tracing; shielded Monero flows are generally not traceable with standard tools.
  • Analytics supports risk scoring at onboarding, transaction screening, alert investigation, and source-of-funds work.
CCAS-D2 · 35%

AML Foundations for Cryptoasset and Blockchain

Financial crime types
  • Money laundering: disguising proceeds of crime as legitimate. Three stages: placement (getting dirty value into the system, e.g. cash into a crypto ATM), layering (obscuring the trail: wallet hops, mixers, chain hopping, conversions), integration (using the cleaned value: property, business, cash-out).
  • Structuring / smurfing: breaking amounts into smaller transactions below reporting or verification thresholds, in fiat or crypto.
  • Terrorist financing: moving value to support terrorism. Funds can be legitimately sourced, amounts are often small, and detection leans on counterparties and context rather than transaction size.
  • Sanctions evasion: obscuring the involvement of sanctioned persons or jurisdictions, e.g. P2P trades, VPNs, chain hopping, front companies.
  • Fraud: investment scams, phishing, Ponzi schemes (BitConnect), rug pulls, romance-investment scams.
  • Bribery and corruption: crypto used to pay or hide bribes; gifts and PEP relationships are the classic fact patterns.
  • Tax evasion (illegal concealment or misreporting, including unreported crypto gains) vs tax avoidance (legal structuring). The Panama Papers is the flagship concealment case study.
  • Cybercrime: ransomware (Colonial Pipeline), exchange hacks, SIM swaps, account takeover. Ransomware payments almost always demand crypto and flow rapidly to mixers and weak-AML exchanges.
ML vs TF in one line: money laundering makes dirty money look clean; terrorist financing often makes clean money do dirty work. Small, unremarkable amounts do not clear a TF concern.
The four risk categories
CategoryCrypto examples
CustomerPEPs, sanctioned parties, shell entities, anonymity-seeking users, other VASPs as customers, customers whose profile does not match activity.
JurisdictionFATF black and grey list countries, weak-AML havens, comprehensively sanctioned territories, geographic mismatch between KYC, IP and transaction patterns.
ProductPrivacy coins, mixers, P2P features, crypto ATMs, lending and leverage, NFTs, cross-chain bridges, prepaid access.
ChannelNon-face-to-face onboarding, third-party or agent onboarding, API and programmatic access, remote deposit capture in traditional finance.

Underneath these sit institutional risk types: operational, legal, concentration and reputational. Exam questions often describe a scenario and ask you to name the category, so practise classifying quickly.

Crypto-specific risks
  • Privacy coins: severely reduced traceability; many VASPs decline to list them or restrict them under risk appetite.
  • Mixers and tumblers: deliberate obfuscation. Regulators have hit mixers hard: FinCEN penalised Helix and Bitcoin Fog operators, and OFAC designated Blender.io and Tornado Cash in 2022 (the first sanctioned mixers, including a smart-contract-based one).
  • Dark markets: drugs, stolen data, CSAM. Direct on-chain exposure to darknet market addresses is among the strongest red flags there is, and CSAM-linked flows are hard-stop, zero-tolerance territory.
  • Smart contract and DeFi risk: code exploits (reentrancy, oracle manipulation, flash loans), no intermediary to apply KYC, and stolen funds laundered at speed through bridges and mixers, often landing at exchange deposit addresses.
  • DEX risk: no gatekeeper, so illicit funds swap freely; your exposure arrives when proceeds reach your platform.
  • Gaming and NFT risk: in-game assets and NFTs as value-transfer rails, and wash trading: selling an asset between wallets you control at inflated prices to fabricate value or legitimise funds.
  • Indirect sanctions risk: you can inherit exposure several hops away, or via counterparty VASPs with poor controls.
Red flags for virtual assets

Drawn from the FATF virtual asset red flag indicators. Learn them as patterns, not a checklist:

  • Deposits immediately withdrawn or converted with no trading or economic rationale (pass-through behaviour).
  • Structuring: many transactions kept just under identification or reporting thresholds.
  • Funding from many unrelated wallets or accounts that consolidate then exit (smurfing aggregation).
  • Immediate conversion to privacy coins, or use of mixers, tumblers and anonymising services.
  • Direct or close exposure to darknet markets, ransomware, scam or sanctioned addresses.
  • Use of IP anonymisers, Tor, or logins inconsistent with the KYC profile.
  • Incomplete, false or reluctant KYC information; multiple accounts under one identity.
  • Profile mismatch: sudden high-volume activity from a dormant or low-income account, or an older customer abruptly trading crypto (possible scam victim).
  • Peel chain: a long series of hops where small slices peel off to other addresses (often exchanges) while the remainder rolls forward. Chain hopping: rapid conversion across assets and chains to frustrate tracing. Both are layering signatures.
Controls: KYC, monitoring, screening
  • KYC manages risk at the relationship level: identify and verify the customer, understand expected activity, and keep it current. Risk-based intensity: simplified, standard, or enhanced due diligence.
  • Transaction monitoring is behavioural: rules and models watch activity over time and raise alerts after the fact (velocity, structuring, pass-through, exposure scenarios). Systems need tuning to the crypto context or they drown analysts in false positives.
  • Sanctions screening is list-based and must run in real time: customers and counterparties against sanctions lists, and wallet exposure against designated addresses, at onboarding and continuously.
Monitoring vs screening is a favourite exam contrast. Screening asks "is this party on a list right now?" Monitoring asks "does this behaviour make sense over time?" One is a match, the other is a pattern.
  • Escalation runs from alert, to analyst review, to investigation, to the MLRO deciding whether to report. Controls span the whole customer life cycle: onboarding, ongoing, and exit.
CCAS-D3 · 35%

Risk Management Programs for Cryptoasset and Blockchain

FATF and international bodies
  • FATF: the intergovernmental AML/CFT standard-setter. Its 40 Recommendations are soft law: binding in practice through national implementation and peer pressure, not directly enforceable.
  • Recommendation 15 (amended 2019, plus the 2019 and updated 2021 guidance) extends the full AML/CFT toolkit to virtual assets and VASPs: licensing or registration, supervision, CDD, record-keeping, STR filing and sanctions compliance.
  • Recommendation 16, the Travel Rule: for VA transfers, the originating VASP must obtain and transmit originator and beneficiary information to the beneficiary VASP, which must receive and retain it. FATF's suggested threshold is USD/EUR 1,000.
  • Mutual evaluation reports: FATF peer reviews of how well a country implements the standards, driving grey and black listing decisions.
  • Grey list = jurisdictions under increased monitoring with agreed action plans. Black list = high-risk jurisdictions subject to a call for action, where countermeasures can apply (Iran, DPRK, Myanmar).
  • Supporting cast: UN (binding sanctions via Security Council), Wolfsberg Group (bank industry AML guidance), Basel Committee (prudential and risk-management standards for banks), Egmont Group (the network connecting national FIUs for intelligence exchange), World Bank and IMF (assessments and technical assistance). MLATs formalise cross-border legal assistance.
Travel Rule data set: originator name, originator account or wallet identifier, and one of address, national ID number, or date and place of birth, plus beneficiary name and beneficiary account or wallet identifier. Purpose of payment and tax IDs are not part of it.
United States regime
  • Bank Secrecy Act: the foundation. Crypto exchangers and administrators are money services businesses under FinCEN's 2013 and 2019 CVC guidance: register with FinCEN, maintain an AML program, file SARs (MSB threshold USD 2,000) and CTRs for cash over USD 10,000, and keep records.
  • USA PATRIOT Act: expanded BSA powers. Section 311 lets Treasury designate a foreign jurisdiction or institution a primary money laundering concern and impose special measures, up to banning correspondent accounts. Sections 312 to 319 cover correspondent and private banking due diligence; 314(a) and 314(b) enable information sharing with government and between institutions.
  • AML Act of 2020: modernised the BSA, explicitly covering businesses transmitting value that substitutes for currency, created the beneficial ownership registry (Corporate Transparency Act), and strengthened whistleblower incentives.
  • OFAC: administers sanctions on a strict liability basis: no intent or knowledge required for a violation. The SDN list has included crypto addresses since 2018. Ransomware advisories (2020, 2021) warn that facilitating ransom payments to sanctioned actors risks penalties.
  • AML Act 2020, more detail the guide stresses: created a national beneficial ownership database at FinCEN, added whistleblower protections, set national AML/CFT priorities (corruption, fraud, cybercrime, TF, transnational crime, drugs, human trafficking, proliferation financing), and recast SARs as intelligence tools that should be highly useful to law enforcement.
  • GENIUS Act (signed 18 July 2025): the US framework for payment stablecoin issuers. A payment stablecoin is built for payment or settlement, redeemable for a fixed monetary amount, designed to hold that value, and is not a national currency, deposit or security. Issuers above USD 10 billion market cap face federal oversight; smaller issuers may opt for a state regime that is substantially similar. Issuers are treated as financial institutions under the BSA, must run full AML and sanctions programs, and must be able to freeze, block or burn tokens on lawful order. Foreign issuers must register with the OCC.
EU and UK regimes
  • 5AMLD (from January 2020): first EU-wide AML coverage of fiat-crypto exchange platforms and custodian wallet providers.
  • The 2024 "Single Rulebook" AML package, four instruments: 6AMLD (directive: CDD, central beneficial ownership registers, stronger FIUs; member states transpose by July 2027), AMLR (directly applicable regulation harmonising CDD and risk assessment, an EU-wide EUR 10,000 cap on cash payments, tighter PEP and beneficial ownership rules, wider scope including football clubs and agents; applies July 2027, football provisions 2029), AMLA-R (creates the EU Anti-Money Laundering Authority, which will directly supervise selected high-risk obliged entities from 2028), and the TFR.
  • MiCA: the EU market rulebook for crypto. CASP authorisation with passporting across the EU, classification of cryptoassets, consumer protection, and reserve and governance rules for stablecoin issuers. MiCA sits beside the AML framework rather than replacing it.
  • TFR (EU Travel Rule, in force 30 December 2024 alongside MiCA's CASP rules): originator name, address and wallet address plus beneficiary name and wallet address travel before or with the transfer. No minimum threshold. The receiving CASP must detect missing data and either reject or suspend the transfer or take reasonable steps to obtain it. Prohibits anonymous crypto accounts. Self-hosted wallet transfers above EUR 1,000 require verifying the customer controls the wallet (the Satoshi test is one way).
  • TFR carve-outs: pure person-to-person transfers with no CASP involved, and transfers where providers act on their own account rather than for a customer.
  • UK (outside the EU since January 2020, so not bound by 6AMLD): key laws are the Proceeds of Crime Act 2002, the Terrorism Act 2000, and the Money Laundering Regulations 2017 as amended in 2019. Two regulated crypto business types: cryptoasset exchange providers and custodian wallet providers, registered with and supervised by the FCA. UK VASPs sit inside the existing AML framework, so every AML rule applies to them.
Threshold contrast: FATF R.16 suggests USD/EUR 1,000. EU TFR has no threshold for CASP transfers. The EUR 1,000 figure in TFR attaches to self-hosted wallet verification. AMLR's EUR 10,000 is a cash payment cap, unrelated to the Travel Rule.
Risk assessment methodology
  • Risk-based approach: identify and assess your risks, then allocate controls and resources in proportion. Required by FATF Recommendation 1.
  • The working equation: inherent risk, less the effect of controls, equals residual risk. Inherent risk is what you face with no controls; residual is what remains after controls operate.
  • Risk appetite: a board-approved statement of the amount and type of risk the firm will accept. Residual risk must land inside appetite, or you add controls, restrict the activity, or exit it. Document a residual risk action plan for anything outside appetite.
  • Assess across customer, jurisdiction, product and channel, with crypto-specific overlays: privacy coin exposure, VASP counterparties, high-risk customer types. Run a dedicated sanctions risk assessment.
  • Risk-rate customers using your institution's methodology plus third-party tools (blockchain analytics scores, screening vendors), and report results to senior management and the board.
AML program design
  • Pillars of the program: internal policies, procedures and controls; a designated compliance officer (the MLRO); ongoing employee training; independent testing or audit; and customer due diligence with ongoing monitoring rounding out the modern five-pillar frame.
  • MLRO: owns the program day to day, receives internal suspicion escalations, decides whether to file reports with the FIU, and fronts contact with regulators and law enforcement.
  • Three lines of defense: first line is the business (front office, onboarding, operations) owning risk where it arises; second line is compliance and risk, setting policy, advising and monitoring independently; third line is internal audit, independently testing the whole framework.
  • Supporting structures: culture of compliance set from the top, dual controls on sensitive actions, know-your-employee and vendor screening, and documented, maintained policies.
Independence is the tell. If a question asks who can both design controls and independently test them, the answer is nobody: second line advises and monitors, third line audits, and neither belongs to the business it checks.
KYC, EDD and Know Your VASP
  • CDD for a natural person: identify, verify against reliable independent sources, screen, and establish purpose and expected activity. For a legal person: add formation documents, ownership structure, and identify and verify beneficial owners.
  • EDD triggers: PEPs, high-risk jurisdictions, complex structures, unexplained activity, high-risk products. EDD means senior management approval, establishing source of wealth and source of funds, and enhanced ongoing monitoring.
  • Source of funds = where the money in this relationship or transaction came from. Source of wealth = how the customer accumulated their overall net worth. Different questions, both required for EDD.
  • Know Your VASP: due diligence on counterparty VASPs before or while transacting with them: licensing and registration status, ownership, quality of the AML program, and on-chain exposure profile. A counterparty exchange with weak controls imports its risk into your flows.
  • On-chain data extends KYC: wallet history and exposure inform source of funds in a way traditional finance cannot match.
Investigations and reporting
  • Investigations start from alerts, referrals, negative news, law enforcement requests, or blockchain tracing leads. Keep an investigative mindset: follow evidence, document as you go, protect the organisation (use anonymised research access so targets cannot detect scrutiny).
  • Research in structured steps: internal data, blockchain analysis, open-source intelligence, then external inquiries, matched to the blockchain in question. Ask "how much research is reasonably enough" and record the answer.
  • SAR/STR structure: a narrative answering who, what, when, where, why and how, written so a law enforcement reader can act on it. In the US, file within 30 days of detection (60 if no suspect identified).
  • No tipping off. Never reveal to the customer that a report was filed or an investigation exists.
  • Law enforcement contact runs through defined channels. A written request may ask you to keep an account open for monitoring; otherwise, exit decisions follow your policy: refuse, restrict or terminate, with sanctions hits handled as hard stops rather than exit-as-usual.
  • FIUs receive and analyse reports; some are administrative, some sit inside law enforcement. Egmont connects them across borders.
ALL DOMAINS

Case files and ACAMS framing

Case files the guide uses

The study guide teaches through named cases. Know the one-line lesson of each; exam scenarios borrow their shape.

  • Blender.io (May 2022): the first mixer OFAC put on the SDN list, for laundering Lazarus Group (North Korea) hack proceeds and Russian-linked ransomware. Lesson: mixer exposure can be sanctions exposure; block and report.
  • Tornado Cash (2022): an open-source, smart-contract mixer on Ethereum that was also sanctioned. Real-world note: Treasury lifted those sanctions in March 2025, but the exam lesson is the same: smart-contract mixers obscure source of funds.
  • SUEX (September 2021): first virtual currency exchange sanctioned anywhere, Czech-registered, around 40% of volume tied to illicit actors including ransomware. Lesson: VASPs that facilitate ransomware cash-outs are sanctions targets.
  • Helix and Coin Ninja (October 2020): FinCEN's first enforcement action against a mixer, a USD 60 million penalty on operator Larry Dean Harmon. Lesson: mixers are money services businesses with full BSA duties.
  • Welcome to Video (October 2019): a CSAM site paid in bitcoin, taken down by tracing payments. 337 users arrested across 38 countries and 23 children rescued. Lesson: Bitcoin is pseudonymous and traceable.
  • Colonial Pipeline (2021): DarkSide, a ransomware-as-a-service group, extracted a roughly USD 4 million bitcoin ransom. Investigators traced part of it to one wallet, obtained the private key and seized it.
  • Bitfinex hack (2016): 119,756 BTC stolen. Small amounts were laundered through darknet markets and gift cards; arrests and seizure of most funds came in 2022. Lesson: tracing can succeed years later.
  • BitConnect (2016 to 2018): a Ponzi scheme marketing a "trading bot" with returns up to 40% a month, an ICO token and paid promoters. Lesson: guaranteed outsized returns and referral rewards are fraud markers.
  • Toebbe (2021): a former US Navy engineer sold nuclear secrets for Monero because he feared Bitcoin's traceability. Lesson: privacy coins appeal to criminals precisely because they defeat tracing.
  • TerraUSD (May 2022): an algorithmic stablecoin lost its peg and collapsed. Lesson: algorithmic designs carry run risk.
  • Mashreq (2021): UAE bank's London branch pushed over 1,700 USD transfers worth more than USD 4 billion through US banks for Sudan-linked parties (2005 to 2009). NYDFS fined USD 100 million. Lesson: correspondent banking hides beneficiaries and creates sanctions exposure.
  • Binance (2023): charged for serving US persons without MSB registration and without effective AML and sanctions controls. Lesson: BSA obligations follow US customers, wherever the exchange is based.
  • UK cash-to-crypto courier (2019): a courier caught with GBP 170,000 cash was collecting for a Dubai network and paying it to face-to-face crypto exchangers, about GBP 1 million in six days. Prosecuted under POCA and jailed. Lesson: UK AML law treats crypto laundering exactly like fiat laundering.
  • South Africa structuring: over 150 people and several shell companies split purchases across multiple VASPs and sent them abroad, laundering more than USD 100 million. Lesson: structuring and mules work in crypto too.
  • Malta grey listing: grey-listed in 2021, removed in June 2022. Lesson: once a jurisdiction leaves the list, review the purpose of transactions with EDD rather than relying on the jurisdiction label alone.
  • Elder fraud alert: a new, older customer buys crypto by debit card, sends it straight to a self-hosted wallet, then on to a low-KYC exchange. Lesson: the customer is likely a scam victim; protect, investigate and report.
  • Panama Papers: a leak describing over 200,000 shell companies set up through Mossack Fonseca. Lesson: shell companies conceal beneficial owners.
  • Voice phishing, the "gifts" scenario, and the Deutsche Bank AI KYC project round out fraud, bribery and technology. Lessons: social engineering harvests ID data, gifts create corruption risk, and AI in KYC needs careful implementation and partners.
Answer in ACAMS's words

When the official material frames a concept a particular way, the exam answer usually follows that framing even where industry shorthand differs. These are the framings worth matching.

  • Three control types: preventive (due diligence, recordkeeping), detective (monitoring, screening), corrective (fixing gaps after detection). Examples of control strategies: policies, training, four-eyes checks (a second person reviews the work), segregation of duties.
  • Risks when financial crime controls fail: operational, legal, concentration (over-reliance on one partner, funder or service, such as a single banking partner) and reputational. Regulatory and financial risk also appear in the material.
  • Lines of defense: first line is front-line, customer-facing staff; second line identifies and mitigates risk and documents functions, and must stay independent; third line is internal audit, which builds an audit risk assessment to set priorities.
  • The MLRO oversees the AML program and is the person who files (and typically writes) the SAR.
  • Controls across the customer lifecycle: KYC, transaction monitoring, investigations.
  • Timing: screening runs in real time at onboarding and on an ongoing basis; transaction monitoring runs after the customer is accepted and transacting.
  • Four research steps: Assess, Explore, Organize, Present.
  • Reasonable research: enough that someone else could reach and justify the same conclusion from your documentation and steps.
  • Valid findings: court records, reporting from reliable outlets, and concrete evidence such as screenshots. Unverified rumour is not a finding.
  • Customer profile layout: summary, basic information, nature of business, red flags, issues of concern.
  • Escalation path: internal review group, internal escalation report, then SAR (or UAR) to the authorities.
  • After a SAR: regular review and enhanced monitoring, any legal restrictions, and possible changes to or exit from the relationship. Rejecting a customer follows policy; reasons to exit include suspicious activity or a change in the firm's risk appetite.
  • Law enforcement requests: first verify the request is legal and relevant, then respond through the defined channel.
  • PEP types: foreign, domestic, international organisation.
  • Source of funds evidence: recent pay slip, bank statement, tax return. Source of wealth looks at the customer's total wealth and how it was built.
  • Sanctions evasion families: payment-related, trade-related, ownership-related. Who imposes sanctions: the UN Security Council, the EU, and individual states.
  • Attribution: linking real-world entities to anonymous addresses. Judge sources on origin, format, date, and how many independent sources corroborate.
  • Mutual legal assistance: treaty channels (MLATs, requested via an MLAR) for evidence that cannot be passed police to police. Extraterritoriality: a state enforcing its rules beyond its borders (the US FCPA is the classic example).
  • UN bodies: the GPML helps member states build AML laws, institutions and skills; the 1988 Vienna Convention first defined money laundering offences, in the drug-trafficking context.
  • Crypto gaming risk: inconsistent compliance rules across countries plus gaming's long history as a laundering channel. Smart contract fraud markers: unrealistic promised returns and promoters not registered with any regulator.
  • Machine learning in AFC: lower cost, better efficiency, new candidate solutions. New technology helps with risk management, efficiency, client experience and work quality.

Flashcard drill

Key facts, case files and glossary terms for instant recall. Tap a card to flip it, then grade yourself honestly: Again sends it to the back of the deck, Got it retires it. Domain decks include that domain\'s glossary terms.

TAP TO REVEAL

Glossary

Plain-language definitions of the terms the CCAS material uses. Type to filter.

Question bank

150 original questions in the CCAS scenario style, with instant feedback and explanations. Filter by domain, or open My misses to clear everything you got wrong here or in a mock. Multi-select questions state how many answers to pick and are graded all-or-nothing, like the real exam.

Mock exam

Each attempt draws a fresh set from the 150-question bank at the real blueprint (30 / 35 / 35), so repeat mocks are not the same paper. Score 75% or better to clear the simulated pass line; aim for 85% before booking.

Sit it like the real thing: one sitting, no notes, answer everything. Flag anything shaky and return in the final pass.

Exam-day strategy

The CCAS is a scenario exam. It rewards judgment applied through a risk-based lens, not recall alone. These habits are what separate a 75 from an 85.

Answering technique

  • Answer every question. There is no penalty for guessing. A blank is a guaranteed zero.
  • Read the last sentence first in long scenarios. Knowing the actual ask ("what should the analyst do FIRST", "which is the STRONGEST indicator") tells you what to look for in the stem.
  • Watch the qualifiers: first, next, best, most, strongest. Several options are often defensible; the exam wants the priority action. Escalate-per-policy usually beats heroic unilateral action, and risk-based beats zero-tolerance except for sanctions and CSAM, which are hard stops.
  • Multi-select is all-or-nothing. The question says how many to pick. Pick exactly that many, and confirm each selection independently earns its place.
  • Eliminate absolutes. Options claiming "always", "never", "fully anonymous" or "completely untraceable" are usually wrong. Blockchain is pseudonymous; controls are risk-based.
  • Swap-check technical distractors. D1 wrong answers love giving PoW the properties of PoS, UTXO the properties of accounts, or hot wallets the properties of cold.

Time management

  • 100 questions in 175 minutes = 1:45 each. Checkpoint yourself: question 35 by 60 minutes, question 70 by 120 minutes, leaving a 15-minute review buffer.
  • First pass: answer everything, flag anything uncertain, never sit on one question past 3 minutes. Second pass: flagged items only.
  • Change an answer on review only when you can articulate a reason. Vague second-guessing flips more right answers to wrong than the reverse.

Facts to have cold before you walk in

  • The 3 domains and weights, the 5 FATF VASP activities, the Travel Rule data set and the USD/EUR 1,000 threshold, and the TFR's no-threshold rule with EUR 1,000 self-hosted wallet verification.
  • The FATF list labels: grey = increased monitoring, black = call for action.
  • The 3 ML stages, the 4 risk categories, the program pillars, the 3 lines of defense.
  • Residual risk = inherent risk after controls, and that residual must sit inside board-approved appetite.
  • OFAC strict liability, SDN wallet listings since 2018, US SAR timing (30 days, 60 without a subject), CTR at USD 10,000 cash, MSB SAR threshold USD 2,000.
  • Monero: ring signatures and stealth addresses by default. Zcash: shielding optional. Pseudonymous, never anonymous.
  • Bitcoin: 21 million cap, 100 million satoshis per coin, halving every 210,000 blocks.
  • GENIUS Act: July 2025, USD 10 billion federal line, issuers are BSA financial institutions, freeze/block/burn. EU package: 6AMLD, AMLR (EUR 10,000 cash cap), AMLA-R (AMLA supervises from 2028), TFR (no threshold, from 30 December 2024).
  • ACAMS lists: preventive/detective/corrective controls; Assess, Explore, Organize, Present; foreign/domestic/international organisation PEPs; payment/trade/ownership sanctions evasion.

Weekend plan for a Monday sitting

  • Friday evening (2 hours): one 25-question sprint cold to find your weakest domain. Then read that domain's notes plus the two cross-domain topics.
  • Saturday: morning, the full timed mock in one sitting. Afternoon, review every miss until you can say why each wrong option is wrong. Evening, flashcards on your weakest domain and the case files deck.
  • Sunday: morning, clear the My misses list in the question bank. Afternoon, a second full mock (it will be a different paper). Evening, glossary deck and the facts list above only. Stop by 9 pm.
  • Monday: 20 minutes of flashcards on the D3 regulation cards (GENIUS, Single Rulebook, TFR), then nothing new. Check your ID and exam confirmation, arrive or log in early.